skills/xoai/sage/sage-memory/Gen Agent Trust Hub

sage-memory

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructs the agent to use standard local commands such as git rev-parse to determine the project root directory, which is necessary for correct database indexing in worktree environments.
  • [SAFE]: Knowledge and learning data are stored locally in the .sage-memory/ and .sage/docs/ directories. This behavior is restricted to the project workspace and does not access sensitive system paths or credentials.
  • [SAFE]: The skill utilizes the sage-memory CLI and MCP tools for scanning codebases and managing the knowledge graph. These are vendor-provided utilities intended for project analysis and context enrichment.
  • [SAFE]: While the skill processes project-specific files as a knowledge source (which inherently involves reading data), it does not involve untrusted remote sources or malicious execution patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 07:37 AM
Security Audit — agent-trust-hub — sage-memory